CVE-2021-45343
published 2022-01-25CVE-2021-45343: In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document.
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.90%
55.6th percentile
In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | librecad | < librecad 2.1.3-3 (bookworm) | librecad 2.1.3-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| librecad | librecad | — | — |
| librecad | librecad | >= 0 < 2.1.3-1.3+deb11u1 | 2.1.3-1.3+deb11u1 |
| librecad | librecad | >= 0 < 2.1.3-3 | 2.1.3-3 |
| librecad | librecad | >= 0 < 2.1.3-3 | 2.1.3-3 |
| librecad | librecad | >= 0 < 2.1.3-3 | 2.1.3-3 |
| librecad | librecad | >= 0 < 2.1.3-1.2+deb10u1build0.20.04.1 | 2.1.3-1.2+deb10u1build0.20.04.1 |
| librecad | librecad | >= 0 < 2.0.9-2ubuntu0.1~esm1 | 2.0.9-2ubuntu0.1~esm1 |
| librecad | librecad | >= 0 < 2.1.2-1ubuntu0.1~esm1 | 2.1.2-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LibreCAD vulnerabilities
vendor_ubuntu·2023-03-15·CVSS 7.8
CVE-2021-21899 [HIGH] LibreCAD vulnerabilities
Title: LibreCAD vulnerabilities
Summary: Several security issues were fixed in LibreCAD.
Cody Sixteen discovered that LibreCAD incorrectly
handled memory when parsing DXF files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-19105)
Lilith of Cisco Talos discovered that LibreCAD incorrectly
handled memory when parsing DWG files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service, or possibly execute arbitrary code.
(CVE-2021-21898, CVE-2021-21899)
Lilith of Cisco Talos discovered that LibreCAD incorrectly
handled memory when parsing DRW files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of se
Debian
CVE-2021-45343: librecad - In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw ...
vendor_debian·2021·CVSS 5.5
CVE-2021-45343 [MEDIUM] CVE-2021-45343: librecad - In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw ...
In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document.
Scope: local
bookworm: resolved (fixed in 2.1.3-3)
bullseye: resolved (fixed in 2.1.3-1.3+deb11u1)
forky: resolved (fixed in 2.1.3-3)
sid: resolved (fixed in 2.1.3-3)
trixie: resolved (fixed in 2.1.3-3)
OSV
librecad vulnerabilities
osv·2023-03-15·CVSS 7.8
CVE-2018-19105 [HIGH] librecad vulnerabilities
librecad vulnerabilities
Cody Sixteen discovered that LibreCAD incorrectly
handled memory when parsing DXF files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-19105)
Lilith of Cisco Talos discovered that LibreCAD incorrectly
handled memory when parsing DWG files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service, or possibly execute arbitrary code.
(CVE-2021-21898, CVE-2021-21899)
Lilith of Cisco Talos discovered that LibreCAD incorrectly
handled memory when parsing DRW files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service, or possibly execute arbitrary code.
(CVE-2021-21900)
Albi
GHSA
GHSA-xcgm-pvwf-mjq7: In LibreCAD 2
ghsa_unreviewed·2022-02-15
CVE-2021-45343 [MEDIUM] CWE-476 GHSA-xcgm-pvwf-mjq7: In LibreCAD 2
In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document.
OSV
CVE-2021-45343: In LibreCAD 2
osv·2022-01-25·CVSS 5.5
CVE-2021-45343 [MEDIUM] CVE-2021-45343: In LibreCAD 2
In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/LibreCAD/LibreCAD/issues/1468https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCC2FZ6HZOIK3775K4MTCOUHX6PLGPEL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VUMH3CWGVSMR2UIZEA35Q5UB7PDVVVYS/https://security.gentoo.org/glsa/202305-26https://www.debian.org/security/2022/dsa-5077https://github.com/LibreCAD/LibreCAD/issues/1468https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCC2FZ6HZOIK3775K4MTCOUHX6PLGPEL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VUMH3CWGVSMR2UIZEA35Q5UB7PDVVVYS/https://security.gentoo.org/glsa/202305-26https://www.debian.org/security/2022/dsa-5077
2022-01-25
Published